<!DOCTYPE html>





<html lang="zh-CN">
<head>
  <meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=2">
<meta name="theme-color" content="#222">
<meta name="generator" content="Hexo 3.9.0">
  <link rel="apple-touch-icon" sizes="180x180" href="/images/apple-touch-icon-next.png?v=7.4.0">
  <link rel="icon" type="image/png" sizes="32x32" href="/images/favicon-32x32.png?v=7.4.0">
  <link rel="icon" type="image/png" sizes="16x16" href="/images/favicon-16x16.png?v=7.4.0">
  <link rel="mask-icon" href="/images/avatar.svg?v=7.4.0" color="#222">
  <link rel="alternate" href="/atom.xml" title="Anemone's Blog" type="application/atom+xml">
  <meta name="google-site-verification" content="Re5JdegRYzNFco-rC9lYIsvSWIgh5JvyfhuEaZCeFCk">
  <meta name="baidu-site-verification" content="opTC8YN3Pn">

<link rel="stylesheet" href="/css/main.css?v=7.4.0">


<link rel="stylesheet" href="https://cdn.bootcss.com/font-awesome/4.7.0/css/font-awesome.min.css">


<script id="hexo-configurations">
  var NexT = window.NexT || {};
  var CONFIG = {
    root: '/',
    scheme: 'Pisces',
    version: '7.4.0',
    exturl: false,
    sidebar: {"position":"left","display":"post","offset":12,"onmobile":false},
    copycode: {"enable":false,"show_result":false,"style":null},
    back2top: {"enable":true,"sidebar":false,"scrollpercent":false},
    bookmark: {"enable":false,"color":"#222","save":"auto"},
    fancybox: false,
    mediumzoom: false,
    lazyload: false,
    pangu: false,
    algolia: {
      appID: 'GB90MXPJ1C',
      apiKey: '05d808da3baf50ac2f2fad2dc3a3cd8f',
      indexName: 'dev_blog',
      hits: {"per_page":20},
      labels: {"input_placeholder":"Search for Posts","hits_empty":"We didn't find any results for the search: ${query}","hits_stats":"${hits} results found in ${time} ms"}
    },
    localsearch: {"enable":false,"trigger":"auto","top_n_per_article":1,"unescape":true,"preload":false},
    path: 'search.xml',
    motion: {"enable":true,"async":false,"transition":{"post_block":"fadeIn","post_header":"slideDownIn","post_body":"slideDownIn","coll_header":"slideLeftIn","sidebar":"slideUpIn"}},
    translation: {
      copy_button: '复制',
      copy_success: '复制成功',
      copy_failure: '复制失败'
    },
    sidebarPadding: 40
  };
</script>

  <meta name="description" content="在软件安全中，最常见的漏洞有注入类漏洞（Injection）和信息泄露（Information Leak），而本节课将介绍的Information Flow 分析方法可以有效处理以上漏洞，具体来说，就是我们常用的污点分析技术。Information Flow Security">
<meta name="keywords" content="白盒扫描,静态程序分析,污点分析,Information flow">
<meta property="og:type" content="article">
<meta property="og:title" content="静态程序分析课程笔记（安全）">
<meta property="og:url" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/index.html">
<meta property="og:site_name" content="Anemone&#39;s Blog">
<meta property="og:description" content="在软件安全中，最常见的漏洞有注入类漏洞（Injection）和信息泄露（Information Leak），而本节课将介绍的Information Flow 分析方法可以有效处理以上漏洞，具体来说，就是我们常用的污点分析技术。Information Flow Security">
<meta property="og:locale" content="zh-CN">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905193021433.png">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905194503470.png">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905202944738.png">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905204725605.png">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905204756009.png">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905205129601.png">
<meta property="og:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905205353856.png">
<meta property="og:updated_time" content="2020-09-09T13:10:39.975Z">
<meta name="twitter:card" content="summary">
<meta name="twitter:title" content="静态程序分析课程笔记（安全）">
<meta name="twitter:description" content="在软件安全中，最常见的漏洞有注入类漏洞（Injection）和信息泄露（Information Leak），而本节课将介绍的Information Flow 分析方法可以有效处理以上漏洞，具体来说，就是我们常用的污点分析技术。Information Flow Security">
<meta name="twitter:image" content="http://anemone.top/pl-静态程序分析课程笔记（安全）/image-20200905193021433.png">
  <link rel="canonical" href="http://anemone.top/pl-静态程序分析课程笔记（安全）/">


<script id="page-configurations">
  // https://hexo.io/docs/variables.html
  CONFIG.page = {
    sidebar: "",
    isHome: false,
    isPost: true,
    isPage: false,
    isArchive: false
  };
</script>

  <title>静态程序分析课程笔记（安全） | Anemone's Blog</title>
  








  <noscript>
  <style>
  .use-motion .brand,
  .use-motion .menu-item,
  .sidebar-inner,
  .use-motion .post-block,
  .use-motion .pagination,
  .use-motion .comments,
  .use-motion .post-header,
  .use-motion .post-body,
  .use-motion .collection-header { opacity: initial; }

  .use-motion .logo,
  .use-motion .site-title,
  .use-motion .site-subtitle {
    opacity: initial;
    top: initial;
  }

  .use-motion .logo-line-before i { left: initial; }
  .use-motion .logo-line-after i { right: initial; }
  </style>
</noscript>

</head>

<body itemscope itemtype="http://schema.org/WebPage" lang="zh-CN">
  <div class="container use-motion">
    <div class="headband"></div>

    <header id="header" class="header" itemscope itemtype="http://schema.org/WPHeader">
      <div class="header-inner"><div class="site-brand-container">
  <div class="site-meta">

    <div>
      <a href="/" class="brand" rel="start">
        <span class="logo-line-before"><i></i></span>
        <span class="site-title">Anemone's Blog</span>
        <span class="logo-line-after"><i></i></span>
      </a>
    </div>
  </div>

  <div class="site-nav-toggle">
    <button aria-label="切换导航栏">
      <span class="btn-bar"></span>
      <span class="btn-bar"></span>
      <span class="btn-bar"></span>
    </button>
  </div>
</div>


<nav class="site-nav">
  
  <ul id="menu" class="menu">
      
      
      
        
        <li class="menu-item menu-item-home">
      
    

    <a href="/" rel="section"><i class="fa fa-fw fa-home"></i>首页</a>

  </li>
      
      
      
        
        <li class="menu-item menu-item-about">
      
    

    <a href="/about/" rel="section"><i class="fa fa-fw fa-user"></i>关于</a>

  </li>
      
      
      
        
        <li class="menu-item menu-item-tags">
      
    

    <a href="/tags/" rel="section"><i class="fa fa-fw fa-tags"></i>标签</a>

  </li>
      
      
      
        
        <li class="menu-item menu-item-categories">
      
    

    <a href="/categories/" rel="section"><i class="fa fa-fw fa-th"></i>分类</a>

  </li>
      
      
      
        
        <li class="menu-item menu-item-archives">
      
    

    <a href="/archives/" rel="section"><i class="fa fa-fw fa-archive"></i>归档</a>

  </li>
      <li class="menu-item menu-item-search">
        <a href="javascript:;" class="popup-trigger">
        
          <i class="fa fa-search fa-fw"></i>搜索</a>
      </li>
    
  </ul>

</nav>
  <div class="site-search">
    <div class="popup search-popup">
    <div class="search-header">
  <span class="search-icon">
    <i class="fa fa-search"></i>
  </span>
  <div class="search-input" id="search-input"></div>
  <span class="popup-btn-close">
    <i class="fa fa-times-circle"></i>
  </span>
</div>
<div class="algolia-results">
  <div id="algolia-stats"></div>
  <div id="algolia-hits"></div>
  <div id="algolia-pagination" class="algolia-pagination"></div>
</div>

  
</div>
<div class="search-pop-overlay"></div>

  </div>
</div>
    </header>

    
  <div class="back-to-top">
    <i class="fa fa-arrow-up"></i>
    <span>0%</span>
  </div>
  <div class="reading-progress-bar"></div>


    <main id="main" class="main">
      <div class="main-inner">
        <div class="content-wrap">
            

          <div id="content" class="content">
            

  <div id="posts" class="posts-expand">
      <article itemscope itemtype="http://schema.org/Article">
  
  
  
  <div class="post-block post">
    <link itemprop="mainEntityOfPage" href="http://anemone.top/pl-静态程序分析课程笔记（安全）/">

    <span hidden itemprop="author" itemscope itemtype="http://schema.org/Person">
      <meta itemprop="name" content="Anemone">
      <meta itemprop="description" content="关注Web安全、移动安全、Fuzz测试和机器学习">
      <meta itemprop="image" content="/images/avatar.jpg">
    </span>

    <span hidden itemprop="publisher" itemscope itemtype="http://schema.org/Organization">
      <meta itemprop="name" content="Anemone's Blog">
    </span>
      <header class="post-header">
        <h2 class="post-title" itemprop="name headline">静态程序分析课程笔记（安全）

          
        </h2>

        <div class="post-meta">
            <span class="post-meta-item">
              <span class="post-meta-item-icon">
                <i class="fa fa-calendar-o"></i>
              </span>
              <span class="post-meta-item-text">发表于</span>

              
                
              

              <time title="创建时间：2020-09-05 21:22:13" itemprop="dateCreated datePublished" datetime="2020-09-05T21:22:13+08:00">2020-09-05</time>
            </span>
          
            

            
              <span class="post-meta-item">
                <span class="post-meta-item-icon">
                  <i class="fa fa-calendar-check-o"></i>
                </span>
                <span class="post-meta-item-text">更新于</span>
                <time title="修改时间：2020-09-09 21:10:39" itemprop="dateModified" datetime="2020-09-09T21:10:39+08:00">2020-09-09</time>
              </span>
            
          
            <span class="post-meta-item">
              <span class="post-meta-item-icon">
                <i class="fa fa-folder-o"></i>
              </span>
              <span class="post-meta-item-text">分类于</span>
              
                <span itemprop="about" itemscope itemtype="http://schema.org/Thing"><a href="/categories/Program-Language/" itemprop="url" rel="index"><span itemprop="name">Program Language</span></a></span>

                
                
              
            </span>
          

          
            <span id="/pl-静态程序分析课程笔记（安全）/" class="post-meta-item leancloud_visitors" data-flag-title="静态程序分析课程笔记（安全）" title="阅读次数">
              <span class="post-meta-item-icon">
                <i class="fa fa-eye"></i>
              </span>
              <span class="post-meta-item-text">阅读次数：</span>
              <span class="leancloud-visitors-count"></span>
            </span>
          

        </div>
      </header>

    
    
    
    <div class="post-body" itemprop="articleBody">

      
        <p>在软件安全中，最常见的漏洞有注入类漏洞（Injection）和信息泄露（Information Leak），而本节课将介绍的Information Flow 分析方法可以有效处理以上漏洞，具体来说，就是我们常用的污点分析技术。</p><h1 id="Information-Flow-Security"><a href="#Information-Flow-Security" class="headerlink" title="Information Flow Security"></a>Information Flow Security</h1><a id="more"></a>
<h2 id="Information-Flow"><a href="#Information-Flow" class="headerlink" title="Information Flow"></a>Information Flow</h2><blockquote>
<p>Information flow: if the information in variable x is transferred to variable y, then there is information flow x → y. </p>
</blockquote>
<p>信息流[1] 指程序中的变量信息的流动，如有语句<code>y = x</code>，那么存在信息流 $x\rightarrow y$，可以看出，信息流分析很像先前的指针分析。</p>
<h2 id="Access-Control-v-s-Infomation-Flow-Security"><a href="#Access-Control-v-s-Infomation-Flow-Security" class="headerlink" title="Access Control v.s. Infomation Flow Security"></a>Access Control v.s. Infomation Flow Security</h2><ul>
<li><p>访问控制用于检查信息访问的权限，但是无法检查有权限的用户做什么</p>
</li>
<li><p>信息流安全用于检查程序处理数据的安全性，是端到端的信息安全</p>
</li>
</ul>
<p>实际系统中通常需要访问控制和信息流控制两者配合使用。</p>
<h2 id="Information-Flow-Security-1"><a href="#Information-Flow-Security-1" class="headerlink" title="Information Flow Security"></a>Information Flow Security</h2><p>信息流安全主要有两步骤：</p>
<ol>
<li>将变量划分为不同安全等级（Security Levels）</li>
<li>对不同等级的信息流做不同策略（Information Flow）</li>
</ol>
<h3 id="Security-Levels"><a href="#Security-Levels" class="headerlink" title="Security Levels"></a>Security Levels</h3><p>通常对信息流分为两级——高级（H）和低级（L），表示秘密和公开信息。</p>
<p>Dorothy 等人[2] 曾提出用格表示信息流，即 $L\leq H$</p>
<p>实际中也可以有更多级。</p>
<h3 id="Infomation-Flow-Policy"><a href="#Infomation-Flow-Policy" class="headerlink" title="Infomation Flow Policy"></a>Infomation Flow Policy</h3><p>高密级信息不能影响低密级信息，即高密级不能流向低密级，如下图所示：<br><img src="/pl-静态程序分析课程笔记（安全）/image-20200905193021433.png" alt="image-20200905193021433"></p>
<h1 id="Confidentiality-and-Integrity"><a href="#Confidentiality-and-Integrity" class="headerlink" title="Confidentiality and Integrity"></a>Confidentiality and Integrity</h1><p>保密性（Confidentiality）：阻止秘密信息被泄露，可以看出先前的策略就是保证了保密性，信息泄露类漏洞就是违反了保密性；</p>
<p>完整性（Integrity）：保证重要信息不被不可信信息污染，注入类漏洞就是违反了完整性。</p>
<p>下图可以看出Confidentiality和Integrity是对称的，可以视为信息的读安全和写安全：<br><img src="/pl-静态程序分析课程笔记（安全）/image-20200905194503470.png" alt="image-20200905194503470"></p>
<p>这也意味着，可以用相同的技术解决以上两类漏洞。</p>
<h1 id="Explicit-Flow-and-Convert-Channels"><a href="#Explicit-Flow-and-Convert-Channels" class="headerlink" title="Explicit Flow and Convert Channels"></a>Explicit Flow and Convert Channels</h1><p>显示流（Explicit Flow）指直接通过赋值传递信息的流，如：</p>
<ul>
<li><code>x = y</code></li>
<li><code>x = y + z</code></li>
</ul>
<p>隐秘信道（Convert Channels）[4]指通过控制流影响保密数据的信息流，例如如下代码：</p>
<figure class="highlight java"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br></pre></td><td class="code"><pre><span class="line">secret = getSecret();</span><br><span class="line"><span class="keyword">if</span> (secret &lt; <span class="number">0</span>) &#123;</span><br><span class="line">    publik = <span class="number">1</span>;</span><br><span class="line">&#125; <span class="keyword">else</span> &#123;</span><br><span class="line">    publik = <span class="number">0</span>;</span><br><span class="line">&#125;</span><br></pre></td></tr></table></figure>
<p>可以看出，根据 <code>publik</code> 数据可以推测 <code>secret</code> 正负。</p>
<p>通常来说，隐秘信道有以下表现形式</p>
<ul>
<li><p>隐式流（Implicit flows）<br><code>if (secret &lt; 0 ) p = 1; else p = 0;</code></p>
</li>
<li><p>终止信道（Termination channels）<br><code>while ( secret &lt; 0 ) {...};</code></p>
</li>
<li><p>时间信道（Timing channels）<br><code>if ( secret &lt; 0 ) for(...) {...};</code></p>
</li>
<li><p>异常（Exceptions）<br><code>if ( secret &lt; 0 ) throw new Exception(&quot;...&quot;);</code></p>
</li>
</ul>
<p>然而，隐藏信道泄露数据量较小，一般分析至针对显示流。</p>
<h1 id="Taint-Analysis"><a href="#Taint-Analysis" class="headerlink" title="Taint Analysis"></a>Taint Analysis</h1><p>污点分析将数据分为两类，被污染数据和未被污染数据。</p>
<ul>
<li>Source：污点传播源，污点数据常常是一些函数的返回值；</li>
<li>Sink：污点传播至关键点，也叫sink点，常常是敏感函数的参数。</li>
</ul>
<p>对于 Confidentiality，可以其做如下定义：</p>
<ul>
<li>Source：保密数据</li>
<li>Sink：泄露点</li>
</ul>
<p>对于 Integrity，可对其做如下定义：</p>
<ul>
<li>Source：不可信数据</li>
<li>Sink：敏感函数</li>
</ul>
<h2 id="Taint-and-Pointer-Analysis"><a href="#Taint-and-Pointer-Analysis" class="headerlink" title="Taint and Pointer Analysis"></a>Taint and Pointer Analysis</h2><p>污点分析与指针分析非常类似，将污点分析做如下调整，就可以借助指针分析做污点分析：</p>
<ul>
<li>将污点数据作为特殊objects</li>
<li>在allocation sites中产生source</li>
<li>借助指针分析完成污点分析</li>
</ul>
<p>以上下文不敏感的指针分析为例：</p>
<p>首先定义数据抽象：</p>
<p><img src="/pl-静态程序分析课程笔记（安全）/image-20200905202944738.png" alt="image-20200905202944738"></p>
<p>在数据抽象中加入污点数据（Taint Data），$T\subset O$</p>
<p>分析的输入为定义的 source 和 sink，输出为 TaintFlows，记为$<t_i, m> \in TaintFlows$， 表示污点 $t_i$ 传入了敏感函数 $m$ 中。</t_i,></p>
<p>在 call statments 中根据source产生污点 $t_l$：<br><img src="/pl-静态程序分析课程笔记（安全）/image-20200905204725605.png" alt="image-20200905204725605"></p>
<p>剩下的污点传播规则与指针分析一致：<br><img src="/pl-静态程序分析课程笔记（安全）/image-20200905204756009.png" alt="image-20200905204756009"></p>
<p>在call statements中检查污点是否传播到sink：<br><img src="/pl-静态程序分析课程笔记（安全）/image-20200905205129601.png" alt="image-20200905205129601"></p>
<p>下图举例说明了一个在指针分析的同时做污点分析的过程：</p>
<p><img src="/pl-静态程序分析课程笔记（安全）/image-20200905205353856.png" alt="image-20200905205353856"></p>
<p>注意，这里只介绍了最简单的污点分析，真实情况比样例复杂很多，当需要处理其他语句和方法，比如 Java 中字符串拼接方法<code>append()</code>，但是基本思路是不变的。</p>
<h1 id="References"><a href="#References" class="headerlink" title="References"></a>References</h1><ol>
<li>Dorothy E. Denning and Peter J. Denning, “Certification of Programs for Secure Information Flow”. CACM 1977.</li>
<li>Dorothy E. Denning, “A Lattice Model of Secure Information Flow”. CACM 1976.</li>
<li>Ken Biba, “Integrity Considerations for Secure Computer Systems”. Technical Report, ESD-TR-76-372, USAF Electronic Systems Division, Bed-ford, MA, 1977.</li>
<li>Butler W. Lampson, “A Note on the Confinement Problem”. CACM 1973</li>
</ol>

    </div>

    
    
    
        
      
        

<div>
<ul class="post-copyright">
  <li class="post-copyright-author">
    <strong>本文作者： </strong>Anemone</li>
  <li class="post-copyright-link">
    <strong>本文链接：</strong>
    <a href="http://anemone.top/pl-静态程序分析课程笔记（安全）/" title="静态程序分析课程笔记（安全）">http://anemone.top/pl-静态程序分析课程笔记（安全）/</a>
  </li>
  <li class="post-copyright-license">
    <strong>版权声明： </strong>本博客所有文章除特别声明外，均采用 <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/deed.zh" rel="noopener" target="_blank"><i class="fa fa-fw fa-creative-commons"></i>BY-NC-SA</a> 许可协议。转载请注明出处！</li>
</ul>
</div>

      

      <footer class="post-footer">
          
            
          
          <div class="post-tags">
            
              <a href="/tags/白盒扫描/" rel="tag"># 白盒扫描</a>
            
              <a href="/tags/静态程序分析/" rel="tag"># 静态程序分析</a>
            
              <a href="/tags/污点分析/" rel="tag"># 污点分析</a>
            
              <a href="/tags/Information-flow/" rel="tag"># Information flow</a>
            
          </div>
        

        

          <div class="post-nav">
            <div class="post-nav-next post-nav-item">
              
                <a href="/pl-静态程序分析课程笔记（指针分析-上下文敏感）/" rel="next" title="静态程序分析课程笔记（指针分析-上下文敏感）">
                  <i class="fa fa-chevron-left"></i> 静态程序分析课程笔记（指针分析-上下文敏感）
                </a>
              
            </div>

            <span class="post-nav-divider"></span>

            <div class="post-nav-prev post-nav-item">
              
                <a href="/pl-静态程序分析课程笔记（Datalog）/" rel="prev" title="静态程序分析课程笔记（Datalog）">
                  静态程序分析课程笔记（Datalog） <i class="fa fa-chevron-right"></i>
                </a>
              
            </div>
          </div>
        
      </footer>
    
  </div>
  
  
  
  </article>

  </div>


          </div>
          
    
    <div class="comments" id="gitalk-container"></div>
  

        </div>
          
  
  <div class="sidebar-toggle">
    <div class="sidebar-toggle-line-wrap">
      <span class="sidebar-toggle-line sidebar-toggle-line-first"></span>
      <span class="sidebar-toggle-line sidebar-toggle-line-middle"></span>
      <span class="sidebar-toggle-line sidebar-toggle-line-last"></span>
    </div>
  </div>

  <aside class="sidebar">
    <div class="sidebar-inner">
        
        
        
        
      

      <ul class="sidebar-nav motion-element">
        <li class="sidebar-nav-toc">
          文章目录
        </li>
        <li class="sidebar-nav-overview">
          站点概览
        </li>
      </ul>

      <!--noindex-->
      <div class="post-toc-wrap sidebar-panel">
          <div class="post-toc motion-element"><ol class="nav"><li class="nav-item nav-level-1"><a class="nav-link" href="#Information-Flow-Security"><span class="nav-number">1.</span> <span class="nav-text">Information Flow Security</span></a><ol class="nav-child"><li class="nav-item nav-level-2"><a class="nav-link" href="#Information-Flow"><span class="nav-number">1.1.</span> <span class="nav-text">Information Flow</span></a></li><li class="nav-item nav-level-2"><a class="nav-link" href="#Access-Control-v-s-Infomation-Flow-Security"><span class="nav-number">1.2.</span> <span class="nav-text">Access Control v.s. Infomation Flow Security</span></a></li><li class="nav-item nav-level-2"><a class="nav-link" href="#Information-Flow-Security-1"><span class="nav-number">1.3.</span> <span class="nav-text">Information Flow Security</span></a><ol class="nav-child"><li class="nav-item nav-level-3"><a class="nav-link" href="#Security-Levels"><span class="nav-number">1.3.1.</span> <span class="nav-text">Security Levels</span></a></li><li class="nav-item nav-level-3"><a class="nav-link" href="#Infomation-Flow-Policy"><span class="nav-number">1.3.2.</span> <span class="nav-text">Infomation Flow Policy</span></a></li></ol></li></ol></li><li class="nav-item nav-level-1"><a class="nav-link" href="#Confidentiality-and-Integrity"><span class="nav-number">2.</span> <span class="nav-text">Confidentiality and Integrity</span></a></li><li class="nav-item nav-level-1"><a class="nav-link" href="#Explicit-Flow-and-Convert-Channels"><span class="nav-number">3.</span> <span class="nav-text">Explicit Flow and Convert Channels</span></a></li><li class="nav-item nav-level-1"><a class="nav-link" href="#Taint-Analysis"><span class="nav-number">4.</span> <span class="nav-text">Taint Analysis</span></a><ol class="nav-child"><li class="nav-item nav-level-2"><a class="nav-link" href="#Taint-and-Pointer-Analysis"><span class="nav-number">4.1.</span> <span class="nav-text">Taint and Pointer Analysis</span></a></li></ol></li><li class="nav-item nav-level-1"><a class="nav-link" href="#References"><span class="nav-number">5.</span> <span class="nav-text">References</span></a></li></ol></div>
        
      </div>
      <!--/noindex-->

      <div class="site-overview-wrap sidebar-panel">
        <div class="site-author motion-element" itemprop="author" itemscope itemtype="http://schema.org/Person">
    <img class="site-author-image" itemprop="image"
      src="/images/avatar.jpg"
      alt="Anemone">
  <p class="site-author-name" itemprop="name">Anemone</p>
  <div class="site-description" itemprop="description">关注Web安全、移动安全、Fuzz测试和机器学习</div>
</div>
<div class="site-state-wrap motion-element">
  <nav class="site-state">
      <div class="site-state-item site-state-posts">
        
          <a href="/archives/">
        
          <span class="site-state-item-count">70</span>
          <span class="site-state-item-name">日志</span>
        </a>
      </div>
    
      
      
      <div class="site-state-item site-state-categories">
        
          
            <a href="/categories/">
          
        
        <span class="site-state-item-count">31</span>
        <span class="site-state-item-name">分类</span>
        </a>
      </div>
    
      
      
      <div class="site-state-item site-state-tags">
        
          
            <a href="/tags/">
          
        
        <span class="site-state-item-count">86</span>
        <span class="site-state-item-name">标签</span>
        </a>
      </div>
    
  </nav>
</div>
  <div class="feed-link motion-element">
    <a href="/atom.xml" rel="alternate">
      <i class="fa fa-rss"></i>RSS
    </a>
  </div>
  <div class="links-of-author motion-element">
      <span class="links-of-author-item">
      
      
        
      
      
        
      
        <a href="https://github.com/anemone95" title="GitHub &rarr; https://github.com/anemone95" rel="noopener" target="_blank"><i class="fa fa-fw fa-github"></i>GitHub</a>
      </span>
    
      <span class="links-of-author-item">
      
      
        
      
      
        
      
        <a href="mailto:anemone95@qq.com" title="E-Mail &rarr; mailto:anemone95@qq.com" rel="noopener" target="_blank"><i class="fa fa-fw fa-envelope"></i>E-Mail</a>
      </span>
    
  </div>
  <div class="cc-license motion-element" itemprop="license">
    
  
    <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/deed.zh" class="cc-opacity" rel="noopener" target="_blank"><img src="/images/cc-by-nc-sa.svg" alt="Creative Commons"></a>
  </div>



      </div>

    </div>
  </aside>
  <div id="sidebar-dimmer"></div>


      </div>
    </main>

    <footer id="footer" class="footer">
      <div class="footer-inner">
        <div class="copyright">&copy; 2018 – <span itemprop="copyrightYear">2020</span>
  <span class="with-love" id="animate">
    <i class="fa fa-user"></i>
  </span>
  <span class="author" itemprop="copyrightHolder">anemone</span>
</div>
  <div class="powered-by">由 <a href="https://hexo.io" class="theme-link" rel="noopener" target="_blank">Hexo</a> 强力驱动 v3.9.0</div>
  <span class="post-meta-divider">|</span>
  <div class="theme-info">主题 – <a href="https://theme-next.org" class="theme-link" rel="noopener" target="_blank">NexT.Pisces</a> v7.4.0</div>

        






  
  <script>
  function leancloudSelector(url) {
    return document.getElementById(url).querySelector('.leancloud-visitors-count');
  }
  if (CONFIG.page.isPost) {
    function addCount(Counter) {
      var visitors = document.querySelector('.leancloud_visitors');
      var url = visitors.getAttribute('id').trim();
      var title = visitors.getAttribute('data-flag-title').trim();

      Counter('get', `/classes/Counter?where=${JSON.stringify({ url })}`)
        .then(response => response.json())
        .then(({ results }) => {
          if (results.length > 0) {
            var counter = results[0];
            Counter('put', '/classes/Counter/' + counter.objectId, { time: { '__op': 'Increment', 'amount': 1 } })
              .then(response => response.json())
              .then(() => {
                leancloudSelector(url).innerText = counter.time + 1;
              })
            
              .catch(error => {
                console.log('Failed to save visitor count', error);
              })
          } else {
              Counter('post', '/classes/Counter', { title: title, url: url, time: 1 })
                .then(response => response.json())
                .then(() => {
                  leancloudSelector(url).innerText = 1;
                })
                .catch(error => {
                  console.log('Failed to create', error);
                });
            
          }
        })
        .catch(error => {
          console.log('LeanCloud Counter Error', error);
        });
    }
  } else {
    function showTime(Counter) {
      var visitors = document.querySelectorAll('.leancloud_visitors');
      var entries = [...visitors].map(element => {
        return element.getAttribute('id').trim();
      });

      Counter('get', `/classes/Counter?where=${JSON.stringify({ url: { '$in': entries } })}`)
        .then(response => response.json())
        .then(({ results }) => {
          if (results.length === 0) {
            document.querySelectorAll('.leancloud_visitors .leancloud-visitors-count').forEach(element => {
              element.innerText = 0;
            });
            return;
          }
          for (var i = 0; i < results.length; i++) {
            var item = results[i];
            var url = item.url;
            var time = item.time;
            leancloudSelector(url).innerText = time;
          }
          for (var i = 0; i < entries.length; i++) {
            var url = entries[i];
            var element = leancloudSelector(url);
            if (element.innerText == '') {
              element.innerText = 0;
            }
          }
        })
        .catch(error => {
          console.log('LeanCloud Counter Error', error);
        });
    }
  }

  fetch('https://app-router.leancloud.cn/2/route?appId=o5UaCJdPfEG0g7MVxXSMagpT-gzGzoHsz')
    .then(response => response.json())
    .then(({ api_server }) => {
      var Counter = (method, url, data) => {
        return fetch(`https://${api_server}/1.1${url}`, {
          method: method,
          headers: {
            'X-LC-Id': 'o5UaCJdPfEG0g7MVxXSMagpT-gzGzoHsz',
            'X-LC-Key': 'c6IN1PuMV3QPltJcrHfn74Gt',
            'Content-Type': 'application/json',
          },
          body: JSON.stringify(data)
        });
      };
      if (CONFIG.page.isPost) {
        const localhost = /http:\/\/(localhost|127.0.0.1|0.0.0.0)/;
        if (localhost.test(document.URL)) return;
        addCount(Counter);
      } else if (document.querySelectorAll('.post-title-link').length >= 1) {
        showTime(Counter);
      }
    });
  </script>






        
      </div>
    </footer>
  </div>

  
  <script src="//cdn.jsdelivr.net/npm/animejs@3.1.0/lib/anime.min.js"></script>
  <script src="https://cdn.bootcss.com/velocity/1.2.1/velocity.min.js"></script>
  <script src="https://cdn.bootcss.com/velocity/1.2.1/velocity.ui.js"></script>
<script src="/js/utils.js?v=7.4.0"></script><script src="/js/motion.js?v=7.4.0"></script>
<script src="/js/schemes/pisces.js?v=7.4.0"></script>
<script src="/js/next-boot.js?v=7.4.0"></script>



  
  <script>
    (function(){
      var bp = document.createElement('script');
      var curProtocol = window.location.protocol.split(':')[0];
      bp.src = (curProtocol === 'https') ? 'https://zz.bdstatic.com/linksubmit/push.js' : 'http://push.zhanzhang.baidu.com/push.js';
      var s = document.getElementsByTagName("script")[0];
      s.parentNode.insertBefore(bp, s);
    })();
  </script>








  
<link rel="stylesheet" href="//cdn.jsdelivr.net/npm/instantsearch.js@2.10.4/dist/instantsearch.min.css">
<script src="//cdn.jsdelivr.net/npm/instantsearch.js@2.10.4/dist/instantsearch.min.js"></script><script src="/js/algolia-search.js?v=7.4.0"></script>











<script>
if (document.querySelectorAll('pre.mermaid').length) {
  NexT.utils.getScript('//cdn.bootcss.com/mermaid/8.2.6/mermaid.min.js', () => {
    mermaid.initialize({
      theme: 'forest',
      logLevel: 3,
      flowchart: { curve: 'linear' },
      gantt: { axisFormat: '%m/%d/%Y' },
      sequence: { actorMargin: 50 }
    });
  }, window.mermaid);
}
</script>




  

  
    
      
<script type="text/x-mathjax-config">

  MathJax.Hub.Config({
    tex2jax: {
      inlineMath: [ ['$', '$'], ['\\(', '\\)'] ],
      processEscapes: true,
      skipTags: ['script', 'noscript', 'style', 'textarea', 'pre', 'code']
    },
    TeX: {
      equationNumbers: {
        autoNumber: 'AMS'
      }
    }
  });

  MathJax.Hub.Register.StartupHook('TeX Jax Ready', function() {
    MathJax.InputJax.TeX.prefilterHooks.Add(function(data) {
      if (data.display) {
        var next = data.script.nextSibling;
        while (next && next.nodeName.toLowerCase() === '#text') {
          next = next.nextSibling;
        }
        if (next && next.nodeName.toLowerCase() === 'br') {
          next.parentNode.removeChild(next);
        }
      }
    });
  });

  MathJax.Hub.Queue(function() {
    var all = MathJax.Hub.getAllJax(), i;
    for (i = 0; i < all.length; i += 1) {
      element = document.getElementById(all[i].inputID + '-Frame').parentNode;
      if (element.nodeName.toLowerCase() == 'li') {
        element = element.parentNode;
      }
      element.classList.add('has-jax');
    }
  });
</script>
<script>
  NexT.utils.getScript('//cdn.bootcss.com/mathjax/2.7.1/latest.js?config=TeX-AMS-MML_HTMLorMML', () => {
    MathJax.Hub.Typeset();
  }, window.MathJax);
</script>

    
  

  

  

<link rel="stylesheet" href="//cdn.jsdelivr.net/npm/gitalk@1/dist/gitalk.min.css">

<script>
  NexT.utils.getScript('//cdn.jsdelivr.net/npm/gitalk@1/dist/gitalk.min.js', () => {
    var gitalk = new Gitalk({
      clientID: 'f3075553d7b0225df6ca',
      clientSecret: '68362ba87c4cc8e13103afcf729f5bd8ea176a78',
      repo: 'anemone95.github.io',
      owner: 'Anemone95',
      admin: ['Anemone95'],
      id: '3753001451b9ab262a50aae6d972db24',
        language: window.navigator.language || window.navigator.userLanguage,
      
      distractionFreeMode: 'true'
    });
    gitalk.render('gitalk-container');
  }, window.Gitalk);
</script>

</body>
</html>
